CVE-2026-85178 | Helicone VaultManager /v1/vault/key VaultManager.getDecryptedProviderKeyById providerKeyId missing encryption

SecurityVulns

A vulnerability was found in Helicone. It has been declared as problematic. Affected by this issue is the function VaultManager.getDecryptedProviderKeyById of the file /v1/vault/key of the component VaultManager. Such manipulation of the argument providerKeyId leads to missing encryption of sensitive data.

This vulnerability is uniquely identified as CVE-2026-85178. The attack can be launched remotely. No exploit exists.

Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More